x-kom hosting

Zainfekowany komputer przed dysk przenośny c.d.

BedPola
utworzono
utworzono

Pisałam już o podobnym problemie w innym wątku: [url] http://www.forumpc.pl/index.php?showtopic=213767 [/url] niestety został zainfekowany drugi komputer, proszę o pomoc.
Przeskanowałam Malwarebytes'
OTL:
[log] OTL logfile created on: 2011-06-28 17:56:44 - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

767,53 Mb Total Physical Memory | 312,56 Mb Available Physical Memory | 40,72% Memory free
1,83 Gb Paging File | 1,36 Gb Available in Paging File | 74,31% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15,37 Gb Total Space | 4,28 Gb Free Space | 27,83% Space Free | Partition Type: NTFS
Drive D: | 25,69 Gb Total Space | 5,76 Gb Free Space | 22,43% Space Free | Partition Type: NTFS
Drive E: | 10,65 Gb Total Space | 10,59 Gb Free Space | 99,47% Space Free | Partition Type: NTFS
Drive F: | 16,41 Gb Total Space | 1,56 Gb Free Space | 9,53% Space Free | Partition Type: FAT32
Drive G: | 13,46 Gb Total Space | 13,39 Gb Free Space | 99,48% Space Free | Partition Type: NTFS
Drive H: | 48,83 Gb Total Space | 29,12 Gb Free Space | 59,63% Space Free | Partition Type: NTFS
Drive K: | 232,88 Gb Total Space | 34,47 Gb Free Space | 14,80% Space Free | Partition Type: NTFS

Computer Name: SPIKI | User Name: Karo & Pola | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (All) ==========[/color]

PRC - [2011-06-27 20:25:22 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie\OTL.exe
PRC - [2011-06-26 13:44:00 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011-06-26 13:43:58 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2011-02-18 16:30:32 | 007,233,952 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe
PRC - [2011-02-18 16:30:26 | 000,428,088 | ---- | M] () -- C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe
PRC - [2011-02-18 16:28:50 | 000,250,768 | ---- | M] (Samsung) -- C:\Program Files\Samsung\AllShare\AllShareAgent.exe
PRC - [2010-05-21 13:56:04 | 000,499,796 | ---- | M] (Atheros) -- C:\WINDOWS\system32\acs.exe
PRC - [2009-05-14 15:47:54 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2009-05-14 15:47:08 | 002,029,640 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2008-04-14 22:51:52 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2008-04-14 22:51:50 | 000,510,464 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winlogon.exe
PRC - [2008-04-14 22:51:44 | 000,057,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spoolsv.exe
PRC - [2008-04-14 22:51:44 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\smss.exe
PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [RPCSS]
PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETWORKSERVICE]
PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [NETSVCS]
PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [LOCALSERVICE]
PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [IMGSVC]
PRC - [2008-04-14 22:51:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\svchost.exe [DCOMLAUNCH]
PRC - [2008-04-14 22:51:40 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\services.exe
PRC - [2008-04-14 22:51:40 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
PRC - [2008-04-14 22:51:24 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\lsass.exe
PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-04-14 22:51:12 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ctfmon.exe
PRC - [2008-04-14 22:51:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\csrss.exe
PRC - [2008-04-14 22:51:04 | 000,044,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\alg.exe
PRC - [2008-03-20 12:04:46 | 002,127,296 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\gg.exe


[color=#E56717]========== Modules (All) ==========[/color]

MOD - [2011-06-27 20:25:22 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie\OTL.exe
MOD - [2008-04-14 22:51:58 | 000,146,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\winspool.drv
MOD - [2008-04-14 22:50:58 | 000,732,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\userenv.dll
MOD - [2008-04-14 22:50:58 | 000,580,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\user32.dll
MOD - [2008-04-14 22:50:58 | 000,219,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\uxtheme.dll
MOD - [2008-04-14 22:50:58 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wldap32.dll
MOD - [2008-04-14 22:50:58 | 000,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\srclient.dll
MOD - [2008-04-14 22:50:58 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\version.dll
MOD - [2008-04-14 22:50:48 | 008,489,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shell32.dll
MOD - [2008-04-14 22:50:48 | 000,997,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\setupapi.dll
MOD - [2008-04-14 22:50:48 | 000,474,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\shlwapi.dll
MOD - [2008-04-14 22:50:46 | 001,287,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ole32.dll
MOD - [2008-04-14 22:50:46 | 000,584,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rpcrt4.dll
MOD - [2008-04-14 22:50:46 | 000,551,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\oleaut32.dll
MOD - [2008-04-14 22:50:46 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\olepro32.dll
MOD - [2008-04-14 22:50:46 | 000,064,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\samlib.dll
MOD - [2008-04-14 22:50:46 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\secur32.dll
MOD - [2008-04-14 22:50:46 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\psapi.dll
MOD - [2008-04-14 22:50:42 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntmarta.dll
MOD - [2008-04-14 22:50:40 | 000,343,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcrt.dll
MOD - [2008-04-14 22:50:38 | 000,297,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MSCTF.dll
MOD - [2008-04-14 22:50:36 | 001,018,368 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\kernel32.dll
MOD - [2008-04-14 22:50:32 | 000,285,184 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\gdi32.dll
MOD - [2008-04-14 22:50:32 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\framedyn.dll
MOD - [2008-04-14 22:50:16 | 000,822,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comres.dll
MOD - [2008-04-14 22:50:14 | 000,280,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\comdlg32.dll
MOD - [2008-04-14 22:50:12 | 000,498,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\clbcatq.dll
MOD - [2008-04-14 22:50:00 | 000,686,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\advapi32.dll
MOD - [2008-04-14 22:49:16 | 000,714,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntdll.dll
MOD - [2008-04-14 22:46:34 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2008-04-14 22:29:10 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
MOD - [2006-12-21 14:30:44 | 000,102,400 | ---- | M] (Gadu-Gadu S.A.) -- C:\Program Files\Gadu-Gadu\ggwhook.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011-02-18 16:30:32 | 007,233,952 | ---- | M] () [Auto | Running] -- C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe -- (SamsungAllShare)
SRV - [2011-02-18 16:30:22 | 000,022,464 | ---- | M] (Samsung Electronics) [Auto | Stopped] -- C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer)
SRV - [2010-05-21 13:56:04 | 000,499,796 | ---- | M] (Atheros) [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2009-05-14 15:54:22 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009-05-14 15:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2001-10-26 19:30:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (.EsetTrialReset)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2011-05-29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010-09-16 12:12:05 | 000,685,816 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010-05-21 13:56:04 | 000,058,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wsimd.sys -- (WSIMD)
DRV - [2010-01-05 03:31:32 | 001,714,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\athuw.sys -- (AR9271)
DRV - [2009-05-14 15:49:32 | 000,094,360 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009-05-14 15:47:14 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009-05-14 15:41:10 | 000,114,472 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008-04-14 02:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-04-13 22:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C)
DRV - [2007-05-23 05:21:12 | 000,016,272 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2007-05-23 05:20:58 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007-05-11 04:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007-03-27 13:27:02 | 000,543,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007-03-05 07:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007-03-05 06:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007-03-05 06:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007-03-05 06:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2007-03-05 06:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2006-11-21 23:41:18 | 000,022,416 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys -- (BTNetFilter)


[color=#E56717]========== Standard Registry (SafeList) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"

FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-06-26 13:44:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-05-21 18:35:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-09-16 11:47:06 | 000,000,000 | ---D | M]

[2010-09-16 15:14:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Mozilla\Extensions
[2010-09-16 15:14:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Mozilla\Firefox\Profiles\kfz07b2i.default\extensions
[2010-09-16 15:14:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
[2011-06-26 13:44:01 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011-05-21 18:35:16 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2011-05-21 18:35:16 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2011-05-21 18:35:17 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2011-05-21 18:35:17 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2011-05-21 18:35:17 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2011-05-21 18:35:17 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2001-10-26 17:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [AllShareAgent] C:\Program Files\Samsung\AllShare\AllShareAgent.exe (Samsung)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003..\Run: [Fjnont] File not found
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.10.10.1 192.168.3.10
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-09-16 11:28:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2011-06-27 22:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Malwarebytes
[2011-06-27 22:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware
[2011-06-27 22:26:48 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011-06-27 22:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2011-06-27 22:26:42 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011-06-27 22:26:41 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011-06-25 17:43:54 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Karo & Pola\Recent
[2011-06-06 18:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Pulpit\holidayyyyyyyyyyyyyyy
[2011-06-06 18:57:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Picasa 3
[2011-06-06 18:56:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Google
[2011-06-06 18:56:14 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011-06-04 17:39:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Moje dokumenty\My Videos
[2011-06-04 17:39:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Samsung
[2011-06-04 17:22:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Samsung
[2011-06-04 17:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2011-06-04 17:16:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2011-06-04 17:12:26 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011-06-04 17:05:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Downloaded Installations
[2011-06-04 17:04:30 | 035,929,296 | ---- | C] (Samsung Electronics Co., Ltd. ) -- C:\Documents and Settings\Karo & Pola\Pulpit\AllShare_2.0.exe
[2011-06-04 15:59:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Pulpit\mp3karoli
[2011-06-02 18:34:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Pulpit\kacpo

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2011-06-28 15:58:11 | 000,000,316 | -HS- | M] () -- C:\WINDOWS\tasks\Yhtmzfgkys.job
[2011-06-28 15:58:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-06-28 15:58:05 | 804,884,480 | -HS- | M] () -- C:\hiberfil.sys
[2011-06-27 22:26:50 | 000,000,794 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2011-06-27 21:20:48 | 000,285,218 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\295.exe
[2011-06-27 21:13:45 | 000,285,218 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\198.exe
[2011-06-27 21:09:46 | 000,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-06-27 20:42:57 | 000,285,218 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\115.exe
[2011-06-27 20:12:54 | 000,285,218 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\1289.exe
[2011-06-26 01:19:53 | 000,042,496 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-06-25 17:12:33 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-06-20 11:35:24 | 000,135,752 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Pulpit\Iwona Sieradzka.pdf
[2011-06-06 18:57:55 | 000,000,769 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Picasa 3.lnk
[2011-06-04 17:39:14 | 000,001,676 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Samsung AllShare.lnk
[2011-06-04 17:14:34 | 000,490,628 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2011-06-04 17:14:34 | 000,432,492 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-06-04 17:14:34 | 000,083,880 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2011-06-04 17:14:34 | 000,067,448 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-06-04 16:44:12 | 035,929,296 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Documents and Settings\Karo & Pola\Pulpit\AllShare_2.0.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2011-06-27 22:26:50 | 000,000,794 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2011-06-27 21:20:48 | 000,285,218 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\295.exe
[2011-06-27 21:13:45 | 000,285,218 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\198.exe
[2011-06-27 20:42:57 | 000,285,218 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\115.exe
[2011-06-27 20:15:25 | 000,000,316 | -HS- | C] () -- C:\WINDOWS\tasks\Yhtmzfgkys.job
[2011-06-27 20:12:54 | 000,285,218 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\1289.exe
[2011-06-20 11:36:18 | 000,135,752 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Pulpit\Iwona Sieradzka.pdf
[2011-06-06 18:57:55 | 000,000,769 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Picasa 3.lnk
[2011-06-04 17:50:12 | 000,163,120 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2011-06-04 17:39:14 | 000,001,676 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Samsung AllShare.lnk
[2011-04-14 17:38:57 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010-12-22 22:07:10 | 000,000,126 | ---- | C] () -- C:\WINDOWS\rm-win.ini
[2010-10-09 20:52:29 | 000,262,216 | ---- | C] () -- C:\WINDOWS\System32\IPTests.dll
[2010-10-09 20:52:16 | 000,422,000 | ---- | C] () -- C:\WINDOWS\System32\wgapi.dll
[2010-10-09 20:52:16 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\wgapiloc.dll
[2010-09-16 15:14:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010-09-16 14:47:29 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2010-09-16 14:47:29 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2010-09-16 14:47:24 | 000,237,568 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2010-09-16 14:47:24 | 000,212,992 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe
[2010-09-16 14:47:24 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2010-09-16 14:42:30 | 000,003,069 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010-09-16 14:42:29 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010-09-16 13:17:15 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-09-16 13:15:56 | 000,286,904 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-09-16 11:59:47 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010-09-16 11:59:45 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010-09-16 11:59:31 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-09-16 11:59:23 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010-09-16 11:59:01 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-09-16 11:55:18 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-09-16 11:40:08 | 000,042,496 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-09-16 11:32:07 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-09-16 11:23:57 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008-04-14 23:16:20 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006-12-31 08:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001-10-26 18:15:16 | 000,490,628 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat
[2001-10-26 18:15:16 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat
[2001-10-26 18:15:16 | 000,083,880 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat
[2001-10-26 18:15:16 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat
[2001-08-23 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-08-23 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-08-17 23:30:24 | 000,432,492 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001-08-17 23:30:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001-08-17 23:30:24 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001-08-17 23:30:22 | 000,067,448 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001-08-17 23:15:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001-07-22 00:36:48 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001-07-22 00:36:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001-07-22 00:24:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[color=#E56717]========== LOP Check ==========[/color]

[2010-11-20 16:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
[2010-09-16 11:47:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET
[2011-04-20 16:00:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TP-LINK
[2011-04-22 15:38:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\BESTplayer
[2010-09-16 12:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Gadu-Gadu
[2011-05-18 12:26:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\MfcEmbed
[2010-09-16 15:39:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\OpenOffice.org
[2011-06-04 17:39:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Samsung
[2011-06-28 15:58:11 | 000,000,316 | -HS- | M] () -- C:\WINDOWS\Tasks\Yhtmzfgkys.job

[color=#E56717]========== Purity Check ==========[/color]



[color=#E56717]========== Alternate Data Streams ==========[/color]

@Alternate Data Stream - 560039 bytes -> C:\WINDOWS\Temp:temp

< End of report >
[/log]
extras: [log] OTL Extras logfile created on: 2011-06-28 17:56:49 - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

767,53 Mb Total Physical Memory | 312,56 Mb Available Physical Memory | 40,72% Memory free
1,83 Gb Paging File | 1,36 Gb Available in Paging File | 74,31% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15,37 Gb Total Space | 4,28 Gb Free Space | 27,83% Space Free | Partition Type: NTFS
Drive D: | 25,69 Gb Total Space | 5,76 Gb Free Space | 22,43% Space Free | Partition Type: NTFS
Drive E: | 10,65 Gb Total Space | 10,59 Gb Free Space | 99,47% Space Free | Partition Type: NTFS
Drive F: | 16,41 Gb Total Space | 1,56 Gb Free Space | 9,53% Space Free | Partition Type: FAT32
Drive G: | 13,46 Gb Total Space | 13,39 Gb Free Space | 99,48% Space Free | Partition Type: NTFS
Drive H: | 48,83 Gb Total Space | 29,12 Gb Free Space | 59,63% Space Free | Partition Type: NTFS
Drive K: | 232,88 Gb Total Space | 34,47 Gb Free Space | 14,80% Space Free | Partition Type: NTFS

Computer Name: SPIKI | User Name: Karo & Pola | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (SafeList) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[color=#E56717]========== System Restore Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)
"C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe" = C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe:*:Enabled:SimpleSlideShowServer -- (Samsung Electronics)
"C:\Program Files\Samsung\AllShare\AllShare.exe" = C:\Program Files\Samsung\AllShare\AllShare.exe:*:Enabled:SamsungAllSharePCSW -- (Samsung Electronics Co., Ltd.)
"C:\Program Files\Samsung\AllShare\AllShareAgent.exe" = C:\Program Files\Samsung\AllShare\AllShareAgent.exe:*:Enabled:SamsungAllShareAgent -- (Samsung)
"C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe" = C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe:*:Enabled:SamsungAllShareServer -- ()
"C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe" = C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe:*:Enabled:SamsungAllShareHttpServer -- ()


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{036FD544-AED6-3F33-856D-A2292D0CF471}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - PLK
"{30BE2CB7-A171-48BB-9673-9211834956CC}" = OpenOffice.org 3.1
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{481EA8F8-CAC0-4137-9CF8-DD0297593E61}" = TP-LINK Wireless Client Utility
"{644CEC11-C3D3-4F8D-A935-74F1EEF38209}" = ESET NOD32 Antivirus
"{7A2A107B-9695-423F-9462-8F17C178BD35}" = TP-LINK Wireless Client Utility
"{7C77393F-8237-3825-A88A-AFAF3C69C072}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - PLK
"{846AC73B-9394-48B9-B941-8F7F472F0047}" = Bluesoleil2.6.0.9 Release 070606
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1045-7B44-A94000000001}" = Adobe Reader 9.4.1 - Polish
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"{F31E509D-3597-324E-83CF-0C160B2320F0}" = Microsoft .NET Framework 3.5 Language Pack - plk
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALLPlayer_is1" = ALLPlayer V4.X
"CCleaner" = CCleaner (remove only)
"C-Media Audio" = C-Media Audio
"Gadu-Gadu" = Gadu-Gadu 7.7
"InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.7.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware wersja 1.51.0.1200
"Microsoft .NET Framework 3.5 Language Pack - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 — PLK
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MoorHunt_is1" = MoorHunt 0.6.7.2
"Mozilla Firefox 5.0 (x86 pl)" = Mozilla Firefox 5.0 (x86 pl)
"Picasa 3" = Picasa 3
"PROR" = Microsoft Office Professional 2007
"Winamp" = Winamp
"WinRAR archiver" = Archiwizator WinRAR
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

[color=#E56717]========== Last 10 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2011-06-26 05:55:40 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 05:42:20 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 14:40:16 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 14:55:58 | Computer Name = SPIKI | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca Gxs.exe, wersja 2.0.0.295, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-06-27 15:02:05 | Computer Name = SPIKI | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd iexplore.exe, wersja 6.0.2900.5512, moduł
powodujący błąd ntdll.dll, wersja 5.1.2600.5512, adres błędu 0x000109fb.

Error - 2011-06-27 15:10:28 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 15:17:31 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 16:51:37 | Computer Name = SPIKI | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca IEXPLORE.EXE, wersja 6.0.2900.5512, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-06-27 17:15:57 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-28 09:58:27 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

[ System Events ]
Error - 2011-06-27 15:17:36 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą Eset Trial Reset.

Error - 2011-06-27 15:17:36 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Eset Trial Reset z powodu następującego
błędu: %%1053

Error - 2011-06-27 15:20:59 | Computer Name = SPIKI | Source = BROWSER | ID = 8032
Description = Usługa przeglądarki zbyt wiele razy nie zdołała pobrać listy kopii
zapasowych w transporcie \Device\NetBT_Tcpip_{88D12879-99FA-4838-976F-5B7E3AEF6CDB}.
Przeglądarka
zapasowa jest zatrzymywana.

Error - 2011-06-27 17:15:49 | Computer Name = SPIKI | Source = sr | ID = 1
Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd '0xC0000001'
podczas przetwarzania pliku '' w woluminie 'HarddiskVolume1'. W rezultacie zostało
zatrzymane monitorowanie woluminu.

Error - 2011-06-27 17:15:59 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą Eset Trial Reset.

Error - 2011-06-27 17:15:59 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Eset Trial Reset z powodu następującego
błędu: %%1053

Error - 2011-06-27 17:34:07 | Computer Name = SPIKI | Source = BROWSER | ID = 8032
Description = Usługa przeglądarki zbyt wiele razy nie zdołała pobrać listy kopii
zapasowych w transporcie \Device\NetBT_Tcpip_{88D12879-99FA-4838-976F-5B7E3AEF6CDB}.
Przeglądarka
zapasowa jest zatrzymywana.

Error - 2011-06-28 09:58:30 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą Eset Trial Reset.

Error - 2011-06-28 09:58:30 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Eset Trial Reset z powodu następującego
błędu: %%1053

Error - 2011-06-28 10:01:08 | Computer Name = SPIKI | Source = BROWSER | ID = 8032
Description = Usługa przeglądarki zbyt wiele razy nie zdołała pobrać listy kopii
zapasowych w transporcie \Device\NetBT_Tcpip_{88D12879-99FA-4838-976F-5B7E3AEF6CDB}.
Przeglądarka
zapasowa jest zatrzymywana.


< End of report >
[/log]
RSIT:
[log] Logfile of random's system information tool 1.08 (written by random/random)
Run by Karo & Pola at 2011-06-28 18:05:56
Microsoft Windows XP Professional Dodatek Service Pack 3
System drive C: has 4 GB (28%) free of 16 GB
Total RAM: 768 MB (37% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:06:03, on 2011-06-28
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Samsung\AllShare\AllShareAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe
C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie\RSIT.exe
C:\Program Files\trend micro\Karo & Pola.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [AllShareAgent] C:\Program Files\Samsung\AllShare\AllShareAgent.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Fjnont] C:\Documents and Settings\Karo & Pola\Dane aplikacji\Fjnont.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Moduł wstępnego ładowania interfejsu Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demon buforu kategorii składników - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: TP-LINK Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Samsung AllShare PC Service (SamsungAllShare) - Unknown owner - C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe
O23 - Service: SimpleSlideShowServer - Samsung Electronics - C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe

--
End of file - 3826 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Yhtmzfgkys.job

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-05-14 2029640]
"AllShareAgent"=C:\Program Files\Samsung\AllShare\AllShareAgent.exe [2011-02-18 250768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Fjnont"=C:\Documents and Settings\Karo & Pola\Dane aplikacji\Fjnont.exe []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe"="C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe:*:Enabled:SimpleSlideShowServer"
"C:\Program Files\Samsung\AllShare\AllShare.exe"="C:\Program Files\Samsung\AllShare\AllShare.exe:*:Enabled:SamsungAllSharePCSW"
"C:\Program Files\Samsung\AllShare\AllShareAgent.exe"="C:\Program Files\Samsung\AllShare\AllShareAgent.exe:*:Enabled:SamsungAllShareAgent"
"C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe"="C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe:*:Enabled:SamsungAllShareServer"
"C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe"="C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe:*:Enabled:SamsungAllShareHttpServer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-06-28 18:05:57 ----D---- C:\Program Files\trend micro
2011-06-28 18:05:56 ----D---- C:\rsit
2011-06-27 22:26:58 ----D---- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Malwarebytes
2011-06-27 22:26:48 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-06-27 22:26:46 ----D---- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
2011-06-27 22:26:42 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-06-27 22:26:41 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-06-27 21:20:48 ----A---- C:\Documents and Settings\Karo & Pola\Dane aplikacji\295.exe
2011-06-27 21:13:45 ----A---- C:\Documents and Settings\Karo & Pola\Dane aplikacji\198.exe
2011-06-27 20:42:57 ----A---- C:\Documents and Settings\Karo & Pola\Dane aplikacji\115.exe
2011-06-27 20:12:54 ----A---- C:\Documents and Settings\Karo & Pola\Dane aplikacji\1289.exe
2011-06-06 18:57:27 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2011-06-06 18:56:14 ----D---- C:\Program Files\Google
2011-06-04 17:39:19 ----D---- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Samsung
2011-06-04 17:22:13 ----D---- C:\Program Files\Samsung
2011-06-04 17:16:51 ----N---- C:\WINDOWS\system32\spmsg.dll
2011-06-04 17:16:11 ----D---- C:\WINDOWS\SxsCaPendDel
2011-06-04 17:12:26 ----SHD---- C:\Config.Msi

======List of files/folders modified in the last 1 months======

2011-06-28 18:06:03 ----D---- C:\WINDOWS\Prefetch
2011-06-28 18:05:58 ----AD---- C:\WINDOWS\Temp
2011-06-28 18:05:57 ----RD---- C:\Program Files
2011-06-27 23:15:19 ----D---- C:\WINDOWS\system32\drivers
2011-06-27 23:15:19 ----D---- C:\WINDOWS\msapps
2011-06-27 23:15:19 ----D---- C:\WINDOWS
2011-06-27 23:14:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-06-27 23:14:21 ----SD---- C:\WINDOWS\Tasks
2011-06-27 23:14:21 ----D---- C:\WINDOWS\system32
2011-06-27 21:11:26 ----D---- C:\WINDOWS\system32\CatRoot2
2011-06-27 20:40:17 ----SHD---- C:\System Volume Information
2011-06-27 20:40:17 ----D---- C:\WINDOWS\system32\Restore
2011-06-27 20:13:05 ----D---- C:\Documents and Settings
2011-06-26 13:44:13 ----D---- C:\Program Files\Mozilla Firefox
2011-06-25 17:43:56 ----D---- C:\WINDOWS\Debug
2011-06-23 20:17:29 ----D---- C:\Program Files\Gadu-Gadu
2011-06-06 18:57:46 ----HD---- C:\WINDOWS\inf
2011-06-06 18:57:37 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-06-04 18:12:57 ----D---- C:\WINDOWS\Microsoft.NET
2011-06-04 18:12:52 ----RSD---- C:\WINDOWS\assembly
2011-06-04 17:22:35 ----SHD---- C:\WINDOWS\Installer
2011-06-04 17:22:35 ----HD---- C:\Program Files\InstallShield Installation Information
2011-06-04 17:18:28 ----D---- C:\WINDOWS\system32\XPSViewer
2011-06-04 17:18:21 ----D---- C:\WINDOWS\system32\en-us
2011-06-04 17:18:11 ----RSD---- C:\WINDOWS\Fonts
2011-06-04 17:14:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-06-04 17:14:11 ----D---- C:\WINDOWS\WinSxS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\System32\Drivers\vbtenum.sys [2007-03-05 20880]
R0 BTHidMgr;Bluetooth HID Manager Service; C:\WINDOWS\System32\Drivers\BTHidMgr.sys [2007-03-05 35600]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sisagp;Filtr magistrali AGP SIS; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-14 40960]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-09-16 685816]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-05-14 94360]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-05-11 34704]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-03-05 27792]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-05-23 16272]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2002-08-26 417871]
R3 HidUsb;Sterownik Microsoft klasy HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Sterownik myszy HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-26 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-04-14 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-08-17 5888]
R3 rtl8139;Sterownik NT karty Realtek RTL8139(A/B/C)-based PCI Fast Ethernet; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
R3 USBSTOR;Sterownik magazynu masowego USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2010-05-21 58208]
S3 AR5211;TP-LINK Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-03-27 543712]
S3 AR9271;Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athuw.sys [2010-01-05 1714176]
S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-05-23 36496]
S3 BTNetFilter;Bluetooth Network Filter; \??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 usbscan;Sterownik skanera USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ACS;TP-LINK Configuration Service; C:\WINDOWS\system32\acs.exe [2010-05-21 499796]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
R2 SamsungAllShare;Samsung AllShare PC Service; C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe [2011-02-18 7233952]
S2 .EsetTrialReset;Eset Trial Reset; C:\WINDOWS\system32\regedt32.exe [2001-10-26 3584]
S2 SimpleSlideShowServer;SimpleSlideShowServer; C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe [2011-02-18 22464]
S3 aspnet_state;Usuga stanu ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-05-14 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Usługa udostępniania portów Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
[/log]
info: [log] info.txt logfile of random's system information tool 1.08 2011-06-28 18:06:08

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil10i_Plugin.exe -maintain plugin
Adobe Reader 9.4.1 - Polish-->MsiExec.exe /I{AC76BA86-7AD7-1045-7B44-A94000000001}
ALLPlayer V4.X-->"C:\Program Files\ALLPlayer\unins000.exe"
Archiwizator WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Bluesoleil2.6.0.9 Release 070606-->MsiExec.exe /X{846AC73B-9394-48B9-B941-8F7F472F0047}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
C-Media Audio-->C:\WINDOWS\CMIUnInstall.exe
Gadu-Gadu 7.7-->C:\Program Files\Gadu-Gadu\Setup.exe
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
K-Lite Mega Codec Pack 5.7.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Malwarebytes' Anti-Malware wersja 1.51.0.1200-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - PLK-->MsiExec.exe /I{036FD544-AED6-3F33-856D-A2292D0CF471}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - PLK-->MsiExec.exe /I{7C77393F-8237-3825-A88A-AFAF3C69C072}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 Language Pack - plk-->MsiExec.exe /I{F31E509D-3597-324E-83CF-0C160B2320F0}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Professional 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
Microsoft Office Professional 2007-->MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
MoorHunt 0.6.7.2-->"C:\Program Files\MoorHunt\unins000.exe"
Mozilla Firefox 5.0 (x86 pl)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
OpenOffice.org 3.1-->MsiExec.exe /I{30BE2CB7-A171-48BB-9673-9211834956CC}
Pakiet językowy programu Microsoft .NET Framework 3.5 — PLK-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack - plk\setup.exe
Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
Samsung AllShare-->"C:\Program Files\InstallShield Installation Information\{DF47ACA3-7C78-4C08-8007-AC682563C9F1}\setup.exe" -runfromtemp -l0x0415 -removeonly
Samsung AllShare-->MsiExec.exe /I{DF47ACA3-7C78-4C08-8007-AC682563C9F1}
TP-LINK Wireless Client Utility-->"C:\Program Files\InstallShield Installation Information\{7A2A107B-9695-423F-9462-8F17C178BD35}\setup.exe" -runfromtemp -l0x0009 -removeonly
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray-->"C:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.exe"
XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

======System event log======

Computer Name: SPIKI
Event Code: 6009
Message: Microsoft (R) Windows (R) 5.01. 2600 Dodatek Service Pack 3 Uniprocessor Free.

Record Number: 10372
Source Name: EventLog
Time Written: 20110501144729.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 6006
Message: Zatrzymano usługę Dziennik zdarzeń.

Record Number: 10371
Source Name: EventLog
Time Written: 20110501144650.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 7036
Message: Usługa HTTP SSL weszła w stan uruchomienia.

Record Number: 10370
Source Name: Service Control Manager
Time Written: 20110501144627.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 7035
Message: Do usługi HTTP SSL został pomyślnie wysłany kod sterowania uruchom.

Record Number: 10369
Source Name: Service Control Manager
Time Written: 20110501144627.000000+120
Event Type: informacje
User: ZARZĄDZANIE NT\USŁUGA LOKALNA

Computer Name: SPIKI
Event Code: 7036
Message: Usługa Host uniwersalnego urządzenia Plug and Play weszła w stan uruchomienia.

Record Number: 10368
Source Name: Service Control Manager
Time Written: 20110501144626.000000+120
Event Type: informacje
User:

=====Application event log=====

Computer Name: SPIKI
Event Code: 101
Message: wuauclt (2572) Aparat bazy danych został zatrzymany.

Record Number: 5
Source Name: ESENT
Time Written: 20110518102022.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 103
Message: wuaueng.dll (2572) SUS20ClientDataStore: Aparat bazy danych zatrzymał wystąpienie (0).

Record Number: 4
Source Name: ESENT
Time Written: 20110518102022.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 102
Message: wuaueng.dll (2572) SUS20ClientDataStore: Aparat bazy danych uruchomił nowe wystąpienie (0).

Record Number: 3
Source Name: ESENT
Time Written: 20110518101521.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 100
Message: wuauclt (2572) Aparat bazy danych 5.01.2600.5512 został uruchomiony.

Record Number: 2
Source Name: ESENT
Time Written: 20110518101521.000000+120
Event Type: informacje
User:

Computer Name: SPIKI
Event Code: 1800
Message: Usługa Centrum zabezpieczeń systemu Windows została uruchomiona.

Record Number: 1
Source Name: SecurityCenter
Time Written: 20110518101436.000000+120
Event Type: informacje
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 1 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=0103
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------
[/log]

wirusolog
komentarz
komentarz

Jak już został użyty MBAM to może pokażesz ostatni raport?
Raport znajdziesz w zakładkace ,,Logi", patrzysz na datę skanowania i wciskasz przycisk [b]Otwórz[/b].
Wrzucasz całą zawartość.
Poza tym - podobne usuwanie jak na tamtym komputerze.

[hr]

[b]1.[/b] Uruchom OTL i w oknie [b]Własne opcje skanowania/Skrypt[/b] wklej następujący tekst:

[code]
:OTL
@Alternate Data Stream - 560039 bytes -> C:\WINDOWS\Temp:temp

:Files
C:\WINDOWS\tasks\Yhtmzfgkys.job
C:\Documents and Settings\Karo & Pola\Dane aplikacji\295.exe
C:\Documents and Settings\Karo & Pola\Dane aplikacji\198.exe
C:\Documents and Settings\Karo & Pola\Dane aplikacji\115.exe
C:\Documents and Settings\Karo & Pola\Dane aplikacji\1289.exe
C:\Documents and Settings\Karo & Pola\Dane aplikacji\Fjnont.exe

:Reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Fjnont"=-

:Commands
[clearallrestorepoints]
[emptyflash]
[emptytemp][/code]
Kliknij w [b]Wykonaj skrypt[/b]. Zatwierdź restart komputera.

[b]2.[/b] Użyj [url=http://www.hotfix.pl/uzytkowanie-programu-usbfix-a310.htm][b][color=blue][u]USBFix[/url][/b][/color][/u] z opcji [b][color="#FFA500"]DELETION[/color][/b].
Pokaż raport z usuwania.

[b]3.[/b] Następnie uruchamiasz OTL ponownie, tym razem wywołujesz opcję [b]Skanuj[/b]. Pokazujesz nowe logi z OTL + raport z usuwania.

BedPola
komentarz
komentarz

po pierwsze log z MBAM:
[log] Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Wersja bazy: 6963

Windows 5.1.2600 Dodatek Service Pack 3
Internet Explorer 6.0.2900.5512

2011-06-27 23:14:21
mbam-log-2011-06-27 (23-14-21).txt

Typ skanowania: Pełne skanowanie (C:\|D:\|E:\|F:\|G:\|H:\|)
Przeskanowano obiektów: 185670
Upłynęło: 41 minut(y), 12 sekund(y)

Zainfekowanych procesów w pamięci: 1
Zainfekowanych modułów w pamięci: 0
Zainfekowanych kluczy rejestru: 3
Zainfekowanych wartości rejestru: 3
Zainfekowane informacje rejestru systemowego: 0
Zainfekowanych folderów: 0
Zainfekowanych plików: 25

Zainfekowanych procesów w pamięci:
c:\WINDOWS\Gzuvyb.exe (Trojan.FraudPack.Gen) -> 3844 -> Unloaded process successfully.

Zainfekowanych modułów w pamięci:
(Nie znaleziono zagrożeń)

Zainfekowanych kluczy rejestru:
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\W1WIWQ1NPG (Trojan.FakeAlert.SA) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.

Zainfekowanych wartości rejestru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\W1WIWQ1NPG (Trojan.FraudPack.Gen) -> Value: W1WIWQ1NPG -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\R4B1ZAOPF5 (Trojan.FraudPack.Gen) -> Value: R4B1ZAOPF5 -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MSConfig (Trojan.Agent) -> Value: MSConfig -> Quarantined and deleted successfully.

Zainfekowane informacje rejestru systemowego:
(Nie znaleziono zagrożeń)

Zainfekowanych folderów:
(Nie znaleziono zagrożeń)

Zainfekowanych plików:
c:\WINDOWS\Gzuvyb.exe (Trojan.FraudPack.Gen) -> Delete on reboot.
c:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Temp\Gxr.exe (Trojan.FraudPack.Gen) -> Delete on reboot.
c:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Temp\Gxv.exe (Trojan.FraudPack.Gen) -> Delete on reboot.
c:\documents and settings\karo & pola\dane aplikacji\11C.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\dane aplikacji\128B.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\dane aplikacji\1B4.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\dane aplikacji\29B.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\dane aplikacji\fjnont.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\ustawienia lokalne\Temp\Gxq.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\ustawienia lokalne\Temp\Gxs.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\ustawienia lokalne\Temp\Gxt.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\ustawienia lokalne\Temp\Gxu.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\ustawienia lokalne\Temp\Gxw.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\ustawienia lokalne\Temp\Gxx.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
c:\WINDOWS\Gzuvya.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
d:\system volume information\_restore{6d387dcc-718e-491c-a366-8e7db15ea156}\RP5\A0001899.exe (Trojan.Agent) -> Quarantined and deleted successfully.
h:\system volume information\_restore{8553c8b3-c57d-4557-8b6f-108133027a33}\RP423\A0120696.exe (Trojan.Agent) -> Quarantined and deleted successfully.
h:\system volume information\_restore{8553c8b3-c57d-4557-8b6f-108133027a33}\RP423\A0120703.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
h:\system volume information\_restore{8553c8b3-c57d-4557-8b6f-108133027a33}\RP423\A0120795.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\secupdat.dat (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\secupdat.dat (Worm.Autorun) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{22116563-108c-42c0-a7ce-60161b75e508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{bbaeaeaf-1275-40e2-bd6c-bc8f88bd114a}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{810401e2-dde0-454e-b0e2-aa89c9e5967c}.job (Trojan.FraudPack) -> Quarantined and deleted successfully.
c:\documents and settings\karo & pola\hard.exe (Trojan.Agent) -> Quarantined and deleted successfully.
[/log]
logi z OTL:
[log] OTL logfile created on: 2011-06-28 21:05:41 - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

767,53 Mb Total Physical Memory | 406,42 Mb Available Physical Memory | 52,95% Memory free
1,83 Gb Paging File | 1,56 Gb Available in Paging File | 85,18% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: NTFS
Drive D: | 25,69 Gb Total Space | 5,76 Gb Free Space | 22,43% Space Free | Partition Type: NTFS
Drive E: | 10,65 Gb Total Space | 10,59 Gb Free Space | 99,47% Space Free | Partition Type: NTFS
Drive F: | 16,41 Gb Total Space | 14,10 Gb Free Space | 85,91% Space Free | Partition Type: FAT32
Drive G: | 13,46 Gb Total Space | 13,39 Gb Free Space | 99,48% Space Free | Partition Type: NTFS
Drive H: | 48,83 Gb Total Space | 29,84 Gb Free Space | 61,11% Space Free | Partition Type: NTFS
Drive K: | 232,88 Gb Total Space | 36,64 Gb Free Space | 15,73% Space Free | Partition Type: NTFS

Computer Name: SPIKI | User Name: Karo & Pola | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========[/color]

PRC - [2011-06-27 20:25:22 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie\OTL.exe
PRC - [2011-06-26 13:44:00 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009-05-14 15:47:54 | 000,731,840 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2008-04-14 22:51:18 | 001,035,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


[color=#E56717]========== Modules (SafeList) ==========[/color]

MOD - [2011-06-27 20:25:22 | 000,579,072 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie\OTL.exe
MOD - [2008-04-14 22:29:10 | 001,054,208 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll


[color=#E56717]========== Win32 Services (SafeList) ==========[/color]

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011-02-18 16:30:32 | 007,233,952 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe -- (SamsungAllShare)
SRV - [2011-02-18 16:30:22 | 000,022,464 | ---- | M] (Samsung Electronics) [Auto | Stopped] -- C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe -- (SimpleSlideShowServer)
SRV - [2010-05-21 13:56:04 | 000,499,796 | ---- | M] (Atheros) [Auto | Stopped] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2009-05-14 15:54:22 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009-05-14 15:47:54 | 000,731,840 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2001-10-26 19:30:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (.EsetTrialReset)


[color=#E56717]========== Driver Services (SafeList) ==========[/color]

DRV - [2011-05-29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2010-09-16 12:12:05 | 000,685,816 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010-05-21 13:56:04 | 000,058,208 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wsimd.sys -- (WSIMD)
DRV - [2010-01-05 03:31:32 | 001,714,176 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\athuw.sys -- (AR9271)
DRV - [2009-05-14 15:49:32 | 000,094,360 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009-05-14 15:47:14 | 000,107,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009-05-14 15:41:10 | 000,114,472 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008-04-14 02:15:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-04-13 22:05:40 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Sterownik NT karty Realtek RTL8139(A/B/C)
DRV - [2007-05-23 05:21:12 | 000,016,272 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btnetdrv.sys -- (BT)
DRV - [2007-05-23 05:20:58 | 000,036,496 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2007-05-11 04:10:50 | 000,034,704 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007-03-27 13:27:02 | 000,543,712 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007-03-05 07:00:04 | 000,027,792 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2007-03-05 06:56:18 | 000,035,600 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2007-03-05 06:55:12 | 000,020,880 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\vbtenum.sys -- (BTHidEnum)
DRV - [2007-03-05 06:53:18 | 000,044,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2007-03-05 06:52:18 | 000,034,448 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2006-11-21 23:41:18 | 000,022,416 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Program Files\IVT Corporation\BlueSoleil\device\Win2k\BTNetFilter.sys -- (BTNetFilter)


[color=#E56717]========== Standard Registry (All) ==========[/color]


[color=#E56717]========== Internet Explorer ==========[/color]

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_page_url = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
IE - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

[color=#E56717]========== FireFox ==========[/color]

FF - prefs.js..browser.startup.homepage: "http://www.google.pl/"
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17

FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2011-06-04 17:20:29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-06-26 13:44:03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-05-21 18:35:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010-09-16 11:47:06 | 000,000,000 | ---D | M]

[2010-09-16 15:14:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Mozilla\Extensions
[2010-09-16 15:14:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2010-09-16 15:14:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Mozilla\Firefox\Profiles\kfz07b2i.default\extensions
[2010-09-16 15:14:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011-06-26 13:44:03 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) --
[2011-06-26 13:44:01 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2006-10-26 20:12:16 | 000,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
[2010-11-06 12:37:34 | 000,103,864 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
[2011-05-21 18:35:16 | 000,002,767 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\allegro-pl.xml
[2011-05-21 18:35:16 | 000,001,406 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\fbc-pl.xml
[2011-05-21 18:35:17 | 000,002,364 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2011-05-21 18:35:17 | 000,000,917 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\merlin-pl.xml
[2011-05-21 18:35:17 | 000,000,858 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\pwn-pl.xml
[2011-05-21 18:35:17 | 000,001,183 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-pl.xml
[2011-05-21 18:35:17 | 000,001,683 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wp-pl.xml

O1 HOSTS File: ([2001-10-26 17:45:16 | 000,000,742 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\..\Toolbar\ShellBrowser: (&Adres) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\..\Toolbar\WebBrowser: (&Adres) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\..\Toolbar\WebBrowser: (&Łącza) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O4 - HKLM..\Run: [AllShareAgent] C:\Program Files\Samsung\AllShare\AllShareAgent.exe (Samsung)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKU\.DEFAULT..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.10.10.1 192.168.3.10
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\Userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Moduł wstępnego ładowania interfejsu Browseui - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Demon buforu kategorii składników - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (Moja bieżąca strona główna) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-09-16 11:28:19 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2011-06-28 21:02:36 | 000,000,000 | RHSD | M] - C:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011-06-28 21:02:36 | 000,000,000 | RHSD | M] - D:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011-06-28 21:02:36 | 000,000,000 | RHSD | M] - E:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011-06-28 21:02:38 | 000,000,000 | RHSD | M] - F:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2011-06-28 21:02:36 | 000,000,000 | RHSD | M] - G:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011-06-28 21:02:36 | 000,000,000 | RHSD | M] - H:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011-06-28 21:02:36 | 000,000,000 | RHSD | M] - K:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]

[2011-06-28 21:02:36 | 000,000,000 | RHSD | C] -- C:\Autorun.inf
[2011-06-28 20:39:22 | 000,000,000 | ---D | C] -- C:\UsbFix
[2011-06-28 20:30:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2011-06-28 18:05:57 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011-06-28 18:05:56 | 000,000,000 | ---D | C] -- C:\rsit
[2011-06-27 22:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Malwarebytes
[2011-06-27 22:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Malwarebytes' Anti-Malware
[2011-06-27 22:26:48 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011-06-27 22:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dane aplikacji\Malwarebytes
[2011-06-27 22:26:42 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011-06-27 22:26:41 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011-06-25 17:43:54 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Karo & Pola\Recent
[2011-06-06 18:59:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Pulpit\holidayyyyyyyyyyyyyyy
[2011-06-06 18:57:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Picasa 3
[2011-06-06 18:56:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Google
[2011-06-06 18:56:14 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2011-06-04 17:39:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Moje dokumenty\My Videos
[2011-06-04 17:39:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Samsung
[2011-06-04 17:22:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Menu Start\Programy\Samsung
[2011-06-04 17:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\Samsung
[2011-06-04 17:16:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\SxsCaPendDel
[2011-06-04 17:12:26 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011-06-04 17:05:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\Downloaded Installations
[2011-06-04 17:04:30 | 035,929,296 | ---- | C] (Samsung Electronics Co., Ltd. ) -- C:\Documents and Settings\Karo & Pola\Pulpit\AllShare_2.0.exe
[2011-06-04 15:59:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Pulpit\mp3karoli
[2011-06-02 18:34:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Karo & Pola\Pulpit\kacpo

[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]

[2011-06-28 21:02:40 | 000,022,107 | ---- | M] () -- C:\UsbFix_Upload_Me_SPIKI.zip
[2011-06-28 20:35:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-06-28 20:35:08 | 804,884,480 | -HS- | M] () -- C:\hiberfil.sys
[2011-06-27 22:26:50 | 000,000,794 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2011-06-27 21:09:46 | 000,286,904 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011-06-26 01:19:53 | 000,042,496 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-06-25 17:12:33 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-06-20 11:35:24 | 000,135,752 | ---- | M] () -- C:\Documents and Settings\Karo & Pola\Pulpit\Iwona Sieradzka.pdf
[2011-06-06 18:57:55 | 000,000,769 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Picasa 3.lnk
[2011-06-04 17:39:14 | 000,001,676 | ---- | M] () -- C:\Documents and Settings\All Users\Pulpit\Samsung AllShare.lnk
[2011-06-04 17:14:34 | 000,490,628 | ---- | M] () -- C:\WINDOWS\System32\perfh015.dat
[2011-06-04 17:14:34 | 000,432,492 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-06-04 17:14:34 | 000,083,880 | ---- | M] () -- C:\WINDOWS\System32\perfc015.dat
[2011-06-04 17:14:34 | 000,067,448 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-06-04 16:44:12 | 035,929,296 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Documents and Settings\Karo & Pola\Pulpit\AllShare_2.0.exe

[color=#E56717]========== Files Created - No Company Name ==========[/color]

[2011-06-28 21:02:39 | 000,022,107 | ---- | C] () -- C:\UsbFix_Upload_Me_SPIKI.zip
[2011-06-27 22:26:50 | 000,000,794 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Malwarebytes' Anti-Malware.lnk
[2011-06-20 11:36:18 | 000,135,752 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Pulpit\Iwona Sieradzka.pdf
[2011-06-06 18:57:55 | 000,000,769 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Picasa 3.lnk
[2011-06-04 17:50:12 | 000,163,120 | ---- | C] () -- C:\Documents and Settings\LocalService\Ustawienia lokalne\Dane aplikacji\FontCache3.0.0.0.dat
[2011-06-04 17:39:14 | 000,001,676 | ---- | C] () -- C:\Documents and Settings\All Users\Pulpit\Samsung AllShare.lnk
[2011-04-14 17:38:57 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010-12-22 22:07:10 | 000,000,126 | ---- | C] () -- C:\WINDOWS\rm-win.ini
[2010-10-09 20:52:29 | 000,262,216 | ---- | C] () -- C:\WINDOWS\System32\IPTests.dll
[2010-10-09 20:52:16 | 000,422,000 | ---- | C] () -- C:\WINDOWS\System32\wgapi.dll
[2010-10-09 20:52:16 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\wgapiloc.dll
[2010-09-16 15:14:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010-09-16 14:47:29 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2010-09-16 14:47:29 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2010-09-16 14:47:24 | 000,237,568 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2010-09-16 14:47:24 | 000,212,992 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe
[2010-09-16 14:47:24 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2010-09-16 14:42:30 | 000,003,069 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010-09-16 14:42:29 | 000,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2010-09-16 13:17:15 | 000,004,293 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-09-16 13:15:56 | 000,286,904 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010-09-16 11:59:47 | 000,178,176 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010-09-16 11:59:45 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2010-09-16 11:59:31 | 000,205,824 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-09-16 11:59:23 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2010-09-16 11:59:01 | 000,085,504 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-09-16 11:55:18 | 000,881,664 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-09-16 11:40:08 | 000,042,496 | ---- | C] () -- C:\Documents and Settings\Karo & Pola\Ustawienia lokalne\Dane aplikacji\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-09-16 11:32:07 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-09-16 11:23:57 | 000,021,856 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2008-04-14 23:16:20 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2006-12-31 08:57:08 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001-10-26 18:15:16 | 000,490,628 | ---- | C] () -- C:\WINDOWS\System32\perfh015.dat
[2001-10-26 18:15:16 | 000,313,828 | ---- | C] () -- C:\WINDOWS\System32\perfi015.dat
[2001-10-26 18:15:16 | 000,083,880 | ---- | C] () -- C:\WINDOWS\System32\perfc015.dat
[2001-10-26 18:15:16 | 000,034,990 | ---- | C] () -- C:\WINDOWS\System32\perfd015.dat
[2001-08-23 15:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-08-23 15:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-08-17 23:30:24 | 000,432,492 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001-08-17 23:30:24 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001-08-17 23:30:24 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001-08-17 23:30:22 | 000,067,448 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001-08-17 23:15:38 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001-07-22 00:36:48 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001-07-22 00:36:04 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001-07-22 00:24:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat

[color=#E56717]========== LOP Check ==========[/color]

[2010-11-20 16:32:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
[2010-09-16 11:47:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\ESET
[2011-04-20 16:00:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dane aplikacji\TP-LINK
[2011-04-22 15:38:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\BESTplayer
[2010-09-16 12:04:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Gadu-Gadu
[2011-05-18 12:26:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\MfcEmbed
[2010-09-16 15:39:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\OpenOffice.org
[2011-06-04 17:39:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Karo & Pola\Dane aplikacji\Samsung

[color=#E56717]========== Purity Check ==========[/color]



< End of report >
[/log]
Extras:
[log] OTL Extras logfile created on: 2011-06-28 21:05:41 - Run 2
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Documents and Settings\Karo & Pola\Moje dokumenty\Pobieranie
Windows XP Professional Edition Dodatek Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000415 | Country: Polska | Language: PLK | Date Format: yyyy-MM-dd

767,53 Mb Total Physical Memory | 406,42 Mb Available Physical Memory | 52,95% Memory free
1,83 Gb Paging File | 1,56 Gb Available in Paging File | 85,18% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: NTFS
Drive D: | 25,69 Gb Total Space | 5,76 Gb Free Space | 22,43% Space Free | Partition Type: NTFS
Drive E: | 10,65 Gb Total Space | 10,59 Gb Free Space | 99,47% Space Free | Partition Type: NTFS
Drive F: | 16,41 Gb Total Space | 14,10 Gb Free Space | 85,91% Space Free | Partition Type: FAT32
Drive G: | 13,46 Gb Total Space | 13,39 Gb Free Space | 99,48% Space Free | Partition Type: NTFS
Drive H: | 48,83 Gb Total Space | 29,84 Gb Free Space | 61,11% Space Free | Partition Type: NTFS
Drive K: | 232,88 Gb Total Space | 36,64 Gb Free Space | 15,73% Space Free | Partition Type: NTFS

Computer Name: SPIKI | User Name: Karo & Pola | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Extra Registry (All) ==========[/color]


[color=#E56717]========== File Associations ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
.js [@ = JSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1220945662-854245398-1606980848-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[color=#E56717]========== Shell Spawning ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] -- %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
InternetShortcut [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[color=#E56717]========== Security Center Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[color=#E56717]========== System Restore Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

[color=#E56717]========== Firewall Settings ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[color=#E56717]========== Authorized Applications List ==========[/color]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil -- (IVT Corporation.)
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe" = C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe:*:Enabled:SimpleSlideShowServer -- (Samsung Electronics)
"C:\Program Files\Samsung\AllShare\AllShare.exe" = C:\Program Files\Samsung\AllShare\AllShare.exe:*:Enabled:SamsungAllSharePCSW -- (Samsung Electronics Co., Ltd.)
"C:\Program Files\Samsung\AllShare\AllShareAgent.exe" = C:\Program Files\Samsung\AllShare\AllShareAgent.exe:*:Enabled:SamsungAllShareAgent -- (Samsung)
"C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe" = C:\Program Files\Samsung\AllShare\AllShareDMS\WiselinkPro.exe:*:Enabled:SamsungAllShareServer -- ()
"C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe" = C:\Program Files\Samsung\AllShare\AllShareDMS\http_ss_win_pro.exe:*:Enabled:SamsungAllShareHttpServer -- ()


[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{036FD544-AED6-3F33-856D-A2292D0CF471}" = Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - PLK
"{30BE2CB7-A171-48BB-9673-9211834956CC}" = OpenOffice.org 3.1
"{350C9415-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{481EA8F8-CAC0-4137-9CF8-DD0297593E61}" = TP-LINK Wireless Client Utility
"{644CEC11-C3D3-4F8D-A935-74F1EEF38209}" = ESET NOD32 Antivirus
"{7A2A107B-9695-423F-9462-8F17C178BD35}" = TP-LINK Wireless Client Utility
"{7C77393F-8237-3825-A88A-AFAF3C69C072}" = Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - PLK
"{846AC73B-9394-48B9-B941-8F7F472F0047}" = Bluesoleil2.6.0.9 Release 070606
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1045-7B44-A94000000001}" = Adobe Reader 9.4.1 - Polish
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"{F31E509D-3597-324E-83CF-0C160B2320F0}" = Microsoft .NET Framework 3.5 Language Pack - plk
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"ALLPlayer_is1" = ALLPlayer V4.X
"CCleaner" = CCleaner (remove only)
"C-Media Audio" = C-Media Audio
"Gadu-Gadu" = Gadu-Gadu 7.7
"InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.7.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware wersja 1.51.0.1200
"Microsoft .NET Framework 3.5 Language Pack - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 — PLK
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MoorHunt_is1" = MoorHunt 0.6.7.2
"Mozilla Firefox 5.0 (x86 pl)" = Mozilla Firefox 5.0 (x86 pl)
"Picasa 3" = Picasa 3
"PROR" = Microsoft Office Professional 2007
"Usbfix" = UsbFix By TeamXscript
"Winamp" = Winamp
"WinRAR archiver" = Archiwizator WinRAR
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

[color=#E56717]========== Last 10 Event Log Errors ==========[/color]

[ Application Events ]
Error - 2011-06-27 05:42:20 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 14:40:16 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 14:55:58 | Computer Name = SPIKI | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca Gxs.exe, wersja 2.0.0.295, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-06-27 15:02:05 | Computer Name = SPIKI | Source = Application Error | ID = 1000
Description = Aplikacja powodująca błąd iexplore.exe, wersja 6.0.2900.5512, moduł
powodujący błąd ntdll.dll, wersja 5.1.2600.5512, adres błędu 0x000109fb.

Error - 2011-06-27 15:10:28 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 15:17:31 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-27 16:51:37 | Computer Name = SPIKI | Source = Application Hang | ID = 1002
Description = Aplikacja zawieszająca IEXPLORE.EXE, wersja 6.0.2900.5512, moduł zawieszenia
hungapp, wersja 0.0.0.0, adres zawieszenia 0x00000000.

Error - 2011-06-27 17:15:57 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-28 09:58:27 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error - 2011-06-28 14:35:30 | Computer Name = SPIKI | Source = Service1 | ID = 0
Description = Nie można uruchomić usługi. System.IndexOutOfRangeException: Indeks
wykraczał poza granice tablicy. w AllShareSlideShowService.SlideShowService.OnStart(String[]
args) w System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

[ System Events ]
Error - 2011-06-28 14:30:45 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7034
Description = Usługa TP-LINK Configuration Service niespodziewanie zakończyła pracę.
Wystąpiło to razy: 1.

Error - 2011-06-28 14:30:46 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7031
Description = Usługa ESET Service niespodziewanie zakończyła pracę. Wystąpiło to
razy: 1. W przeciągu 0 milisekund zostanie podjęta następująca czynność korekcyjna:
Uruchom usługę ponownie.

Error - 2011-06-28 14:30:46 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7034
Description = Usługa Samsung AllShare PC Service niespodziewanie zakończyła pracę.
Wystąpiło to razy: 1.

Error - 2011-06-28 14:35:32 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7009
Description = Limit czasu (30000 milisekund) podczas oczekiwania na połączenie się
z usługą Eset Trial Reset.

Error - 2011-06-28 14:35:32 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7000
Description = Nie można uruchomić usługi Eset Trial Reset z powodu następującego
błędu: %%1053

Error - 2011-06-28 14:39:49 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7034
Description = Usługa TP-LINK Configuration Service niespodziewanie zakończyła pracę.
Wystąpiło to razy: 1.

Error - 2011-06-28 14:39:49 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7031
Description = Usługa Bufor wydruku niespodziewanie zakończyła pracę. Wystąpiło to
razy: 1. W przeciągu 60000 milisekund zostanie podjęta następująca czynność korekcyjna:
Uruchom usługę ponownie.

Error - 2011-06-28 14:39:49 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7031
Description = Usługa ESET Service niespodziewanie zakończyła pracę. Wystąpiło to
razy: 1. W przeciągu 0 milisekund zostanie podjęta następująca czynność korekcyjna:
Uruchom usługę ponownie.

Error - 2011-06-28 14:39:50 | Computer Name = SPIKI | Source = Service Control Manager | ID = 7034
Description = Usługa Samsung AllShare PC Service niespodziewanie zakończyła pracę.
Wystąpiło to razy: 1.

Error - 2011-06-28 15:00:06 | Computer Name = SPIKI | Source = sr | ID = 1
Description = Filtr Przywracania systemu napotkał nieoczekiwany błąd '0xC000007F'
podczas przetwarzania pliku 'upd.ver' w woluminie 'HarddiskVolume1'. W rezultacie
zostało zatrzymane monitorowanie woluminu.


< End of report >
[/log]
raport z usuwania:
[log] ############################## | UsbFix 7.048 | [Deletion]

User: Karo & Pola (Administrator) # SPIKI [ ]
Updated 11/06/2011 by TeamXscript
Started at 20:39:42 | 28/06/2011
Website: http://www.teamxscript.org
Submit your sample: http://www.teamxscript.org/Upload.php
Contact: TeamXscript.ElDesaparecido@gmail.com

CPU: Intel(R) Celeron(R) CPU 1.70GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Dodatek Service Pack 3
Internet Explorer 6.0.2900.5512

Windows Firewall: Disabled /!\
Antivirus: ESET NOD32 Antivirus 4.0 4.0 [Enabled | (!) Outdated]
RAM -> 768 Mb
C:\ (%systemdrive%) -> Fixed drive # 15 Gb (4 Mb free - 28%) [Windows XP] # NTFS
D:\ -> Fixed drive # 26 Gb (6 Mb free - 22%) [DOWNLOAD] # NTFS
E:\ -> Fixed drive # 11 Gb (11 Mb free - 99%) [GRY] # NTFS
F:\ -> Fixed drive # 16 Gb (2 Mb free - 10%) [ROZRYWKA] # FAT32
G:\ -> Fixed drive # 13 Gb (13 Mb free - 99%) [PROGRAMY] # NTFS
H:\ -> Fixed drive # 49 Gb (29 Mb free - 60%) [Multimedia] # NTFS
I:\ -> CD-ROM
J:\ -> CD-ROM
K:\ -> Fixed drive # 233 Gb (34 Mb free - 15%) [TOSHIBA] # NTFS

################## | Files # Infected Folders |

Deleted ! K:\$RECYCLE.BIN.lnk
Deleted ! K:\Diskeeper.lnk
Deleted ! K:\filmy.lnk
Deleted ! K:\GPS PDA.lnk
Deleted ! K:\ISO.lnk
Deleted ! K:\muzyka.lnk
Deleted ! K:\nokia 6220.lnk
Deleted ! K:\praca diagnostyka dolega.lnk
Deleted ! K:\programy dla mechanika samochodowego.lnk
Deleted ! K:\Programy Projektowe.lnk
Deleted ! K:\Programy.lnk
Deleted ! K:\Recycled.lnk
Deleted ! K:\seba zdjecia.lnk
Deleted ! K:\sterowniki do laptopow.lnk
Deleted ! K:\System Volume Information.lnk
Deleted ! C:\Recycler\S-1-5-21-1220945662-854245398-1606980848-1003
Deleted ! D:\Recycler\S-1-5-21-1220945662-602162358-682003330-1003
Deleted ! D:\Recycler\S-1-5-21-1220945662-854245398-1606980848-1003
Deleted ! D:\Recycler\S-1-5-21-2000478354-287218729-839522115-1003
Deleted ! D:\Recycler\S-1-5-21-2052111302-1060284298-1547161642-1001
Deleted ! E:\Recycler\S-1-5-21-1220945662-602162358-682003330-1003
Deleted ! E:\Recycler\S-1-5-21-1220945662-854245398-1606980848-1003
Deleted ! G:\Recycler\S-1-5-21-1220945662-854245398-1606980848-1003
Deleted ! H:\Recycler\S-1-5-21-1220945662-602162358-682003330-1003
Deleted ! H:\Recycler\S-1-5-21-1220945662-854245398-1606980848-1003
Deleted ! H:\Recycler\S-1-5-21-1417001333-57989841-1177238915-500
Deleted ! H:\Recycler\S-1-5-21-2000478354-287218729-839522115-1003
Deleted ! H:\Recycler\S-1-5-21-2052111302-1060284298-1547161642-1001
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-1002656553-2138681250-2471471778-1001
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2488304306-2876441326-837718913-1000
Deleted ! K:\$RECYCLE.BIN\S-1-5-21-2488304306-2876441326-837718913-1001
Deleted ! K:\Recycler\S-1-5-21-117609710-152049171-1177238915-1003
Deleted ! K:\Recycler\S-1-5-21-1220945662-602162358-682003330-1003
Deleted ! K:\Recycler\S-1-5-21-1220945662-854245398-1606980848-1003
Deleted ! K:\Recycler\S-1-5-21-1343024091-1644491937-682003330-1003
Deleted ! K:\Recycler\S-1-5-21-1390067357-1563985344-1343024091-1003
Deleted ! K:\Recycler\S-1-5-21-1409082233-963894560-1801674531-1003
Deleted ! K:\Recycler\S-1-5-21-1507247247-3120504663-253914542-500
Deleted ! K:\Recycler\S-1-5-21-1606980848-73586283-682003330-1003
Deleted ! K:\Recycler\S-1-5-21-1644491937-308236825-682003330-1003
Deleted ! K:\Recycler\S-1-5-21-1801674531-839522115-854245398-1003
Deleted ! K:\Recycler\S-1-5-21-329068152-1284227242-1417001333-1003
Deleted ! K:\Recycler\S-1-5-21-4020926284-3537673810-3299662691-1008
Deleted ! K:\Recycler\S-1-5-21-448539723-1343024091-1957994488-1003
Deleted ! K:\Recycler\S-1-5-21-484763869-682003330-839522115-1003
Deleted ! K:\Recycler\S-1-5-21-583907252-1450960922-1177238915-1003
Deleted ! K:\Recycler\S-1-5-21-602162358-484061587-1644491937-1003
Deleted ! K:\Recycler\S-1-5-21-725345543-1715567821-1606980848-1003
Deleted ! K:\Recycler\S-1-5-21-725345543-362288127-682003330-1003
Deleted ! K:\Recycler\S-1-5-21-790525478-413027322-682003330-1003
Deleted ! K:\Recycler\S-1-5-21-823518204-117609710-1417001333-1003
Deleted ! K:\Recycler\S-1-5-21-842925246-117609710-839522115-1003
Deleted ! K:\Recycler\S-1-5-21-861567501-1604221776-1606980848-1003
Not deleted ! K:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
Not deleted ! K:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
Deleted ! F:\muza
Deleted ! F:\MUZYKA
Deleted ! K:\MUZYKA

################## | Registry |


################## | Mountpoints2 |


################## | Listing |

[16/09/2010 - 11:28:19 | N | 0] C:\AUTOEXEC.BAT
[16/09/2010 - 11:21:50 | N | 211] C:\boot.ini
[22/07/2001 - 00:13:54 | N | 4952] C:\Bootfont.bin
[04/06/2011 - 17:22:35 | D ] C:\Config.Msi
[16/09/2010 - 11:28:19 | N | 0] C:\CONFIG.SYS
[27/06/2011 - 20:13:05 | D ] C:\Documents and Settings
[28/06/2011 - 20:35:08 | ASH | 804884480] C:\hiberfil.sys
[16/09/2010 - 11:28:19 | N | 0] C:\IO.SYS
[16/09/2010 - 11:28:19 | N | 0] C:\MSDOS.SYS
[18/05/2011 - 12:11:32 | RHD ] C:\MSOCache
[13/04/2008 - 22:13:04 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 00:02:00 | N | 251152] C:\ntldr
[28/06/2011 - 20:35:07 | ASH | 1207959552] C:\pagefile.sys
[28/06/2011 - 18:05:57 | D ] C:\Program Files
[28/06/2011 - 21:01:06 | SHD ] C:\RECYCLER
[28/06/2011 - 18:06:08 | D ] C:\rsit
[28/06/2011 - 20:30:53 | SHD ] C:\System Volume Information
[28/06/2011 - 21:01:06 | D ] C:\UsbFix
[28/06/2011 - 21:01:06 | A | 4502] C:\UsbFix.txt
[27/06/2011 - 23:15:19 | D ] C:\WINDOWS
[28/06/2011 - 20:30:44 | D ] C:\_OTL
[16/09/2010 - 10:12:19 | D ] D:\ca38792d9b5951d8403701
[22/09/2009 - 13:16:05 | D ] D:\David Guetta - One Love (Special Edition) [2009]
[19/12/2008 - 18:23:10 | D ] D:\Diskeeper
[22/04/2011 - 15:35:10 | D ] D:\filmy
[22/09/2009 - 12:11:12 | D ] D:\Goraca 20 Radia Eska - notowanie 687 z dn. 11.09.2009
[20/05/2011 - 11:21:55 | D ] D:\Moorhunt
[16/09/2010 - 10:09:46 | D ] D:\Pobierane Firefox
[28/06/2011 - 21:01:06 | SHD ] D:\RECYCLER
[16/09/2010 - 11:34:37 | SHD ] D:\System Volume Information
[22/09/2009 - 12:11:21 | D ] D:\VA-RMF FM Najlepsza Muzyka Pod Sloncem 2009-2CD
[28/06/2011 - 21:01:06 | SHD ] E:\RECYCLER
[16/09/2010 - 11:34:37 | SHD ] E:\System Volume Information
[18/11/2002 - 17:24:42 | SHD ] F:\RECYCLED
[30/07/2007 - 18:01:18 | D ] F:\FOUND.000
[10/08/2007 - 22:52:32 | D ] F:\FOUND.001
[18/08/2007 - 10:23:40 | D ] F:\DC
[16/09/2008 - 09:12:00 | N | 5566049] F:\07 - Alex Gaudino feat Shena - Watch out
[27/12/2008 - 10:00:48 | D ] F:\FOUND.002
[08/01/2009 - 17:24:08 | D ] F:\FOUND.003
[23/11/2002 - 19:59:50 | SHD ] F:\System Volume Information
[19/05/2008 - 15:57:28 | N | 3651000] F:\Rihanna - Take a bow.mp3
[24/09/2008 - 23:57:06 | D ] F:\Katy Perry - One Of The Boys 2008
[19/12/2009 - 16:42:06 | N | 3206196] F:\agnieszka chylinska - zla.mp31261237282_[mp3.teledyski.info].mp3
[18/07/2009 - 07:47:38 | N | 3534574] F:\andrzej_grabowski_jestem_jak_motyl_jest_dobrze.mp3
[19/12/2009 - 16:42:20 | N | 3418938] F:\agnieszka chylinska - fochb0%19.mp31261237207_[mp3.teledyski.info].mp3
[19/12/2009 - 16:41:26 | N | 4044205] F:\agnieszka chylinska - nie moge cie zapomnie.mp31261237183_[mp3.teledyski.info].mp3
[19/12/2009 - 16:43:06 | N | 4344717] F:\agnieszka chylinska - niebob8927(.mp31261237291_[mp3.teledyski.info].mp3
[19/12/2009 - 16:42:32 | N | 4006169] F:\agnieszka chylinska - wieczny problem9b0d4a7.mp31261237278_[mp3.teledyski.info].mp3
[19/12/2009 - 16:42:20 | N | 3447777] F:\agnieszka chylinska - wybaczam ci9.mp31261237198_[mp3.teledyski.info].mp3
[19/12/2009 - 16:45:12 | N | 4460910] F:\agnieszka chylinska - zima.mp31261237688_[mp3.teledyski.info].mp3
[10/02/2010 - 18:25:04 | N | 4433742] F:\jay-z ft. alicia keys - empire state of mind.mp3
[04/03/2004 - 16:32:14 | D ] F:\INCINERATE
[04/06/2011 - 17:17:23 | D ] G:\63468fcd89796ff9a34656b9
[28/06/2011 - 21:01:06 | SHD ] G:\RECYCLER
[16/09/2010 - 11:34:38 | SHD ] G:\System Volume Information
[19/12/2008 - 18:25:53 | D ] H:\Diskeeper
[10/02/2010 - 14:09:37 | D ] H:\DOKUMENTY
[22/06/2011 - 21:17:40 | D ] H:\FILMY
[12/02/2010 - 22:51:51 | D ] H:\Karoli pendrive
[28/06/2011 - 21:01:06 | SHD ] H:\RECYCLER
[16/09/2010 - 11:34:38 | SHD ] H:\System Volume Information
[05/05/2011 - 17:27:10 | D ] H:\www_misiek
[28/06/2011 - 20:42:47 | SHD ] K:\$RECYCLE.BIN
[30/08/2009 - 22:16:17 | D ] K:\Diskeeper
[21/06/2011 - 00:38:43 | D ] K:\filmy
[26/06/2011 - 23:06:26 | D ] K:\GPS PDA
[02/05/2011 - 12:18:04 | D ] K:\ISO
[26/06/2011 - 22:42:38 | D ] K:\nokia 6220
[21/06/2011 - 20:33:02 | D ] K:\praca diagnostyka dolega
[15/04/2011 - 20:28:35 | D ] K:\Programy
[01/09/2010 - 23:08:35 | D ] K:\programy dla mechanika samochodowego
[21/06/2011 - 00:13:15 | D ] K:\Programy Projektowe
[20/09/2009 - 13:08:09 | D ] K:\Recycled
[28/06/2011 - 21:01:06 | SHD ] K:\RECYCLER
[23/06/2011 - 00:52:44 | D ] K:\seba zdjecia
[26/06/2011 - 22:42:22 | D ] K:\sterowniki do laptopow
[28/06/2011 - 20:30:53 | SHD ] K:\System Volume Information
[20/10/2009 - 21:49:30 | ASH | 5632] K:\Thumbs.db

################## | Vaccin |

C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
D:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
E:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
F:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
G:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
H:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
K:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)

################## | Upload |

Please send the file: C:\UsbFix_Upload_Me_SPIKI.zip
http://www.teamxscript.org/Upload.php
Thank you for your contribution.

################## | E.O.F |
[/log]

wirusolog
komentarz
komentarz (edytowane)

[quote]
Deleted ! F:\muza
Deleted ! F:\MUZYKA
Deleted ! K:\MUZYKA[/quote]
Chyba wiesz, co masz zrobić? ;)

Kilka małych poprawek.

[hr]

[b]1.[/b] Uruchom OTL i w oknie [b]Własne opcje skanowania/Skrypt[/b] wklej następujący tekst:

[code]
:OTL
O4 - HKLM..\RunOnce: [] File not found

:Files
C:\RECYCLER
D:\RECYCLER
E:\RECYCLER
F:\RECYCLED
F:\FOUND.000
F:\FOUND.001
F:\FOUND.002
F:\FOUND.003
H:\RECYCLER
K:\$RECYCLE.BIN
K:\Recycled
K:\RECYCLER
[/code]
Kliknij w [b]Wykonaj skrypt[/b]. Pokaż raport z usuwania.

BedPola
komentarz
komentarz

Done!
zrobione! muzyke usunelam, ponagrywana na plyty byla kilka lat wstecz, leniom sie nie chcialo usunac z kompa. A ta z dysku to...... do niej sie nie przyznajemy ;) Dziękuję bardzo za pomoc :)
jeszcze przeskanuje MBAM

wirusolog
komentarz
komentarz (edytowane)

Zostały jeszcze kroki końcowe!

[hr]

[b]1.[/b] Uruchom USBFix i wciśnij w nim [b]UNINSTALL[/b].

[b]2.[/b] Uruchom OTL i wciśnij w nim [b]Sprzątanie[/b].

[b]3.[/b] Aktualizacja zabezpieczeń:
[quote]
Internet Explorer [b](Version = 6.0.2900.5512)[/b]
"KLiteCodecPack_is1" = [b]K-Lite Mega Codec Pack 5.7.0[/b]
"Adobe Flash Player Plugin" = [b]Adobe Flash Player 10 Plugin[/b]
[/quote]
[list]
[*]Jest tu bardzo stara wersja IE. Trzeba aktualizować IE bo dużo programów korzysta z silnika, bez Twojej wiedzy, nawet jeżeli korzystasz z Opery. Tak więc aktualizacja do wersji [url=http://windows.microsoft.com/pl-PL/internet-explorer/products/ie/home][b][color=blue][u]8[/url][/b][/color][/u].
[*]Nie jest podana tu konkretna wersja Flash, upewnij się że masz zainstalowany [url="http://get.adobe.com/flashplayer/"][color="#0000FF"][b]Adobe Flash Player 10.3.181.34[/b][/color][/url].
[*]Możesz zaaktualizować kodeki do wersji [url=http://www.dobreprogramy.pl/KLite-Codec-Pack,Program,Windows,13137.html][b][color=blue][u]7.20[/url][/b][/color][/u].[/list]

[b]4.[/b] Wtedy możesz przeprowadzić pełny skan komputera za pomocą MBAM. To co wykryje - usuń i daj raport.

Wciąż szukasz rozwiązania problemu? Napisz teraz na forum!

Możesz zadać pytanie bez konieczności rejestracji - wystarczy, że wypełnisz formularz.

×
×
  • Dodaj nową pozycję...

Powiadomienie o plikach cookie

Strona wykorzystuje pliki cookies w celu prawidłowego świadczenia usług i wygody użytkowników. Warunki przechowywania i dostępu do plików cookies możesz zmienić w ustawieniach przeglądarki.